This policy explains how AfterRevenue processes information when a Shopify merchant installs or uses the app, or when a shopper uses an AfterRevenue post-purchase flow.
Information we process
- Shop and account data: Shopify shop domain, app installation and session information, merchant configuration, subscription status, and authorized staff actions.
- Order and recovery data: Shopify order identifiers, product and quantity details, fulfilment and payment status, requested changes, cancellation or save-offer choices, reorder activity, and recovery outcomes.
- Protected customer data when approved: shipping address, email, and phone only when needed for an eligible correction, lookup, or support request.
- Support and diagnostic data: submitted messages and limited operational logs needed to secure, troubleshoot, and improve the service.
How we use information
We use this information to provide merchant-configured post-purchase recovery, verify whether a requested action is safe and eligible, carry out approved Shopify actions, create attributed reorder links, route checked support context, measure recovery outcomes, prevent misuse, and maintain the service. Issue intelligence gives recommendations to merchants; it does not make legal or similarly significant decisions about shoppers.
Sharing and service providers
AfterRevenue processes information on behalf of the Shopify merchant. Information may be handled by Shopify and infrastructure providers used to operate the app, including Northflank for application hosting and Neon for PostgreSQL. A merchant may configure helpdesk or lifecycle adapters; only checked information needed for that workflow is sent to the provider selected by the merchant. We do not sell personal information.
Retention and deletion
Unless a shorter period is required, expired one-time recovery links are deleted 30 days after expiration; recovery events, completed privacy-request audit records, worker records, and export-delivery records are deleted after 12 months; and personal export payloads in completed privacy requests are removed after 30 days. Active shop configuration and sessions are kept while needed to provide the installed app.
Shopify privacy webhooks process eligible customer data requests, customer redaction, and shop redaction. Shop-owned data is deleted when Shopify sends a valid shop-redaction request. Limited records may be retained longer only when required by law, security, fraud prevention, or an active dispute.
Security and international processing
We use encrypted network connections, encryption at rest, encrypted database backups, scoped Shopify authentication, access controls, synthetic test fixtures, and data-minimization safeguards. Providers may process information in countries other than the merchant or shopper’s country, subject to their contractual and legal safeguards. Read our Security and Data Protection overview.
Your choices
Shoppers should contact the Shopify merchant about an order or the merchant’s privacy practices. Merchants can uninstall AfterRevenue, change configured adapters, or contact us about their app data. Applicable privacy rights vary by location.
Contact
Privacy questions or requests can be sent to singhanhad78@gmail.com.